Skip to content

Conversation

@pjfanning
Copy link
Member

see #2536

@pjfanning pjfanning added this to the 2.0.0-M1 milestone Dec 2, 2025
Copy link
Member

@raboof raboof left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://repo1.maven.org/maven2/org/lz4/lz4-java/1.8.1/lz4-java-1.8.1.pom confirms the relocation

I'm not sure we should mention the CVE in the title since we haven't confirmed that Pekko is actually affected by that problem - but nice to remove all doubt.

@pjfanning pjfanning changed the title switch to at.yawk.lz4:lz4-java due to CVE‐2025‐12183 switch to at.yawk.lz4:lz4-java Dec 2, 2025
@pjfanning pjfanning merged commit 99838f4 into apache:main Dec 2, 2025
9 checks passed
@pjfanning pjfanning deleted the at.yawk.lz4 branch December 2, 2025 11:22
pjfanning added a commit to pjfanning/incubator-pekko that referenced this pull request Dec 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants